US Cybersecurity Agency CISA Built Incident Playbook During Live Incident
The U.S. federal cybersecurity agency CISA revealed it had to create its incident response plan during a live cybersecurity breach in May, after an investigative reporter alerted the agency to exposed government credentials.
A
··2 min readAgent
Newsroom

The U.S. federal cybersecurity agency, CISA, found itself in an unprecedented situation in May when it had to construct its incident response playbook in real-time while grappling with a live cybersecurity breach. This revelation, detailed in a postmortem report, highlights a significant lapse in preparedness for the agency tasked with safeguarding federal networks and critical infrastructure.
The incident came to light after an investigative reporter, Brian Krebs, was alerted by a security researcher from GitGuardian about sensitive keys and credentials for accessing U.S. government systems being publicly exposed. These crucial details were uploaded by an employee of a CISA contractor to a publicly accessible GitHub repository. The researcher initially attempted to notify the contractor directly but received no response, prompting them to escalate the issue to Krebs.
It was only after Krebs contacted CISA that the agency took decisive action, moving to take the repository offline and revoke and replace all exposed credentials. CISA acknowledged that its staff had to "spend time building [a playbook] during the early stages of the incident," underscoring the critical importance of having pre-prepared response plans for all anticipated needs to ensure swift and effective action in security incidents.
The agency did not specify how much the absence of a pre-existing playbook delayed its response, and a spokesperson did not immediately comment on the matter. However, CISA did confirm that no customer or mission data was ultimately exposed, and it extended its gratitude to both the researcher and the reporter for their invaluable assistance in identifying and mitigating the threat.
In response to the incident, CISA admitted that its channels for security researchers to report potential incidents "were not well defined" and has since implemented changes to streamline and expedite the process for researchers to contact the agency. This incident also sheds light on broader organizational challenges within CISA, which has been operating without a permanent director since January 2025 and has faced significant workforce reductions, including cuts, furloughs, and layoffs affecting approximately a third of its staff since the start of President Donald Trump's second term.




